Skip to main content

Overview

NIST Special Publication 800-171 Revision 3 provides requirements for protecting Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organizations. This framework is critical for government contractors and organizations that handle sensitive federal information. Nabla’s automated assessment analyzes your infrastructure-as-code to evaluate compliance against the 110+ security requirements in NIST 800-171 Rev 3.

Framework Details

  • Framework: NIST 800-171
  • Version: Revision 3
  • Control Count: 110+ requirements across 14 families
  • Output Format: OSCAL Assessment Results (JSON)
  • Primary Use Case: CUI protection, government contracting (DFARS compliance)

Assessed Control Families

3.1 Access Control

3.3 Audit and Accountability

3.4 Configuration Management

3.5 Identification and Authentication

3.11 Risk Assessment

3.13 System and Communications Protection

3.14 System and Information Integrity

Multi-Cloud Support

Expanding Beyond AWS: While our initial implementation focuses on AWS resources, we’re actively adding support for:
  • Azure: azurerm_* resources (Key Vault, RBAC, NSGs, Sentinel)
  • Google Cloud: google_* resources (Cloud KMS, IAM, VPC, Security Command Center)
  • Multi-Cloud: Unified compliance posture across hybrid environments
The NIST 800-171 assessor already includes detection for Azure and GCP resource types. Coverage will continue to expand based on customer needs.

Currently Supported Resource Types

AWS Resources
  • aws_iam_user, aws_iam_role, aws_iam_group, aws_iam_policy
  • aws_security_group, aws_network_acl, aws_vpc, aws_subnet
  • aws_cloudtrail, aws_cloudwatch_log_group, aws_cloudwatch_metric_alarm
  • aws_kms_key, aws_kms_alias
  • aws_s3_bucket (with encryption checks)
  • aws_db_instance, aws_rds_cluster (encryption at rest)
  • aws_vpn_gateway, aws_vpn_connection, aws_customer_gateway
  • aws_cognito_user_pool
  • aws_secretsmanager_secret, aws_ssm_parameter
  • aws_guardduty_detector, aws_inspector_assessment_template
  • aws_lb_listener, aws_alb_listener
Azure Resources (Coming Soon!)
  • azurerm_role_assignment, azurerm_role_definition
  • azurerm_network_security_group, azurerm_subnet, azurerm_firewall
  • azurerm_monitor_diagnostic_setting, azurerm_monitor_metric_alert
  • azurerm_key_vault, azurerm_key_vault_key, azurerm_key_vault_secret
  • azurerm_active_directory_user
  • azurerm_virtual_network_gateway, azurerm_virtual_network_peering
  • azurerm_security_center_subscription_pricing
  • azurerm_policy_definition, azurerm_policy_assignment

Assessment Workflow

OSCAL Output Structure

Results conform to OSCAL 1.0.4 Assessment Results format:

Example Assessment Request

Common Findings

High-Severity Issues

3.1.5 - Overly Permissive Policies
3.5.3 - Missing MFA
3.13.11 - Non-FIPS Cryptography

Medium-Severity Issues

3.3.1 - Insufficient Logging
3.13.8 - Unencrypted Transmission

DFARS Compliance

NIST 800-171 compliance is required for:
  • Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012
  • Organizations that process, store, or transmit Controlled Unclassified Information (CUI)
  • DoD contractors and subcontractors
This automated assessment helps demonstrate compliance with DFARS requirements, but should be supplemented with:
  • System Security Plans (SSP)
  • Plan of Action & Milestones (POA&M)
  • Certification from C3PAO (Cyber AB)

Limitations

Important Assessment Limitations:
  • IaC-Only: Only evaluates resources defined in infrastructure code
  • Runtime Gaps: Cannot assess operational security practices, user behavior, or physical security
  • Organizational Controls: Many 800-171 requirements involve policies, procedures, and training
  • Partial Coverage: Some controls (3.1.14, 3.11.1, 3.14.1) require organizational assessment
  • Cloud Provider Trust: Assumes FIPS validation claims by AWS/Azure/GCP are accurate

Best Practices

  1. Layered Assessment: Combine automated IaC scanning with manual policy review
  2. Continuous Monitoring: Run assessments on every infrastructure change
  3. Evidence Retention: Store OSCAL outputs for audit trail and POA&M tracking
  4. Gap Analysis: Use findings to prioritize remediation efforts
  5. Third-Party Validation: Consider C3PAO assessment for official certification

Scoring and POA&M

While Nabla provides automated control assessment, official NIST 800-171 scoring requires:
  • Basic (0-9 points per control)
  • Derived (additive scoring)
  • Plan of Action & Milestones for deficiencies
Use the assessment findings to populate your POA&M:

References